Privacy Policy

Introduction

Welcome to the Bleuno Group Ltd (“BLEUNO”) privacy policy. Bleuno Group Ltd respects your privacy and is committed to protecting your personal data. This privacy policy explains how we look after your personal data when you visit our website (regardless of where you visit from) and informs you of your privacy rights and how the law protects you.

We present this privacy policy in a layered format, allowing you to navigate to specific areas as outlined below. Please also use the Glossary to understand specific terms used throughout this privacy policy.

  • IMPORTANT INFORMATION AND WHO WE ARE
  • THE DATA WE COLLECT ABOUT YOU
  • HOW IS YOUR PERSONAL DATA COLLECTED?
  • HOW WE USE YOUR PERSONAL DATA
  • DISCLOSURES OF YOUR PERSONAL DATA
  • INTERNATIONAL TRANSFERS
  • DATA SECURITY
  • DATA RETENTION
  • YOUR LEGAL RIGHTS
  • GLOSSARY

1. Important Information

Purpose of this Privacy Policy

Bleuno Group Ltd understands the importance of privacy and the protection of your personal data. This policy provides information on how we collect and process your data when you use this website, including data you provide through website interactions. We collect and use personal data only as described here and in line with legal obligations.

Controller

Bleuno Group Ltd is the data controller responsible for your personal data. References to “Bleuno,” “we,” “us,” or “our” in this privacy policy refer to Bleuno Group Ltd as the entity processing your data.

If you have questions about this policy or wish to exercise your legal rights, please contact our data privacy manager at:

Full name of legal entity : Bleuno Group Ltd

Email : dataprivacymanager@bleuno.com

Postal Address : 73, PORTWAY, E15 3QJ

You are entitled to file a complaint with the Information Commissioner's Office (ICO), the UK regulator for data protection issues (www.ico.org.uk), at any time. Please do not hesitate to contact us in the first instance, as we would be grateful for the opportunity to address your concerns before you approach the ICO.

Changes to the privacy policy and your obligation to notify us of them

Our privacy policy undergoes consistent evaluation.

It is crucial that the personal data we possess regarding you is both precise and up-to-date. Please inform us of any modifications to your personal information that occur during your association with us.

External hyperlinks

This website may contain hyperlinks to third-party websites, plug-ins, and applications. Third parties may be able to collect or share data about you if you click on those links or enable those connections. We are not in control of these third-party websites and are not liable for their privacy policies. We recommend that you review the privacy policies of all websites you visit after you depart from our website.

The Data We Collect About You

Personal data, or personal information, means any information about an individual from which that person can be identified. This includes details like name, contact details, identification numbers, and online identifiers. It does not include data where the identity has been removed (anonymous data)

We may collect, use, store, and transfer different kinds of personal data about you, grouped as follows:

  • Identity Data:First name, last name, username, marital status, title, date of birth, and gender.
  • Contact Data:Billing address, delivery address, email, and telephone numbers.
  • Financial Data:Bank account and payment card details.
  • Transaction Data: Details of products and services purchased from us.
  • Technical Data:IP address, browser type, location, and other technology details for website access.
  • Profile Data: Username, password, preferences, feedback, and survey responses.
  • Usage Data:Information on how you use our website, products, and services.
  • Marketing and Communications Data: Preferences for receiving marketing from us and third parties.

We also collect Aggregated Data, such as statistical or demographic data, which may be derived from your personal data but does not reveal your identity. If combined with your personal data, we treat it as personal data

We do not collect any Special Categories of Personal Data about you, which includes information about your health, genetic and biometric data, political opinions, trade union membership, personal life, sexual orientation, religious or philosophical beliefs, and race or ethnicity. We also do not store any information regarding criminal convictions and offences.

If you neglect to submit your personal information

If you neglect to provide the personal data we require due to legal requirements or the terms of a contract we have with you, we may be unable to fulfil the contract we have or are attempting to enter into with you (e.g., to provide you with products or services). In this scenario, we may be required to terminate a product or service that you have with us; however, we will inform you of this at the time.

How Is Your Personal Data Collected?

We use several methods to collect data:

  1. Direct Interactions :Through forms on our website, email, or other communications.
  2. Automated Technologies : Cookies, server logs, and similar technologies capture Technical Data as you interact with our website. [We may also receive Technical Data about you if you visit other websites employing our cookies.] Please see our Cookie Policy for further details.
  3. Third Parties or Public Sources:We may receive data from third parties, like analytics providers (e.g., Google Analytics), advertising networks, and search information providers. [We may also receive Technical Data about you if you visit other websites employing our cookies.] Please see our Cookie Policy for further details.

How We Use Your Personal Data

We will only use your personal data as the law permits. Generally, we will rely on the following legal grounds:

  • Performance of Contract: When we need to fulfill a contract with you
  • Legitimate Interest: When our business needs do not override your rights.
  • Legal Obligation:When we must comply with legal requirements.

Specific uses may include registering new customers, processing orders, managing payments, notifying you of changes, and improving our services. You can opt out of certain types of marketing at any time by following the opt-out instructions in our communications.

To obtain additional information regarding the legal bases upon which we will process your personal data, please refer to the following link: [GLOSSARY, LAWFUL BASIS].

In general, we do not rely on consent as a legal basis for processing your personal data. However, we will obtain your consent prior to transmitting third-party direct marketing communications to you via email or text message for example. You are entitled to revoke your consent to marketing at any time by contacting us.

The purposes for which we will utilise your personal data include:

We have provided a table below that outlines the various methods by which we intend to utilise your personal data, as well as the legal bases on which we rely. Additionally, we have determined our legitimate interests in the appropriate situations.

Please be advised that we may process your personal data for more than one lawful basis, contingent upon the specific purpose for which we are using it. If you require further information regarding the specific legal basis upon which we are processing your personal data, please do not hesitate to contact us. This is particularly true in cases where the table below specifies multiple grounds.

Purpose/ActivityType of DataLawful Basis for Processing (including basis of legitimate interest)
To register you as a new customer(a) Identity
(b) Contact
Performance of a contract with you
To process and deliver your order including:
(a) Manage payments, fees and charges
(b) Collect and recover money owed to us
(a) Identity
(b) Contact
(c) Financial
(d) Transaction
(e) Marketing and Communications
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to recover debts due to us)
To manage our relationship with you which will include:
(a) Notifying you about changes to our terms or privacy policy
(b) Asking you to leave a review or take a survey
(a) Identity
(b) Contact
(c) Profile
(d) Marketing and Communications
(a) Performance of a contract with you
(b) Necessary to comply with a legal obligation
(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)
To enable you to partake in a prize draw, competition or complete a survey(a) Identity
(b) Contact
(c) Profile
(d) Usage
(e) Marketing and Communications
(a) Performance of a contract with you
(b) Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)(a) Identity
(b) Contact
(c) Technical
(a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business reorganisation or group restructuring exercise)
(b) Necessary to comply with a legal obligation
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you(a) Identity
(b) Contact
(c) Profile
(d) Usage
(e) Marketing and Communications
(f) Technical
Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences(a) Technical
(b) Usage
Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
To make suggestions and recommendations to you about goods or services that may be of interest to you(a) Identity
(b) Contact
(c) Technical
(d) Usage
(e) Profile
(f) Marketing and Communications
Necessary for our legitimate interests (to develop our products/services and grow our business)
Marketing

We endeavour to offer you a variety of options with respect to the use of your personal data, particularly in the context of marketing and advertising.

Special promotions from our organisation

We may utilise your Identity, Contact, Technical, Usage, and Profile Data to develop an understanding of what we believe you may require or desire, or what may be of interest to you. This is the process by which we determine which products, services, and offers may be pertinent to you (a process we refer to as marketing). If you have requested information from us or purchased services from us and have not opted out of receiving marketing communications, you will receive them.

Marketing conducted by a third party

Before disclosing your personal information to any third party for marketing purposes, we will obtain your explicit consent via opt-in.

Refusing to participate

You have the option to request that we or third parties cease sending you marketing messages at any time by simply clicking on the opt-out links included in any marketing message that is sent to you. In the event that you choose not to receive these marketing communications, this will not affect personal data that we have collected as a result of a product/service purchase, warranty registration, product/service experience, or other similar transactions.

Cookies

You have the option to configure your browser to either reject all or specific browser cookies, or to notify you when websites establish or access cookies. Please be advised that certain sections of this website may become inaccessible or malfunction if you disable or refuse cookies. Please refer to our Cookie Policy for additional details regarding the cookies we employ.

Modification of objective

Unless we reasonably believe that we need to use your personal data for a different reason and that reason is compatible with the original purpose, we will only use it for the purposes for which it was collected. Please do not hesitate to reach out to us if you would like an explanation of how the processing for the new purpose is consistent with the original purpose.

We will inform you if we need to use your personal data for an unrelated purpose and provide an explanation of the legal basis that enables us to do so.

Please be advised that we may process your personal data without your knowledge or consent, provided that this is required or permitted by law, in accordance with the aforementioned regulations.

Disclosures of Your Personal Data

We may share your personal data with:

  • Service Providers:Third parties providing IT and administrative support
  • Professional Advisors:Including bankers, auditors, and legal advisors.
  • Regulators and Other Authorities:When required for compliance with laws.

If your data is transferred outside the UK, we ensure a similar degree of protection through appropriate safeguards.

RecipientActivity Carried OutSectorLocation
XeroFinancial reporting, invoicing and bookkeeping service.Finance and business supportUS (data stored) / NZ (head office) [Terms of service]
GoogleSEO, PPC & Analytics services, Document managementDigital marketing servicesUS/EU [Privacy Policy]
SalesforceSales & revenue reporting, CRMFinance, sales and business supportUS/UK [Privacy Policy]
Google WorkspaceGoogle products and email serversOperations and business supportUS [Privacy Policy]
HubSpotSales and marketing email managementSales and marketingUS/EU [Data Processing Policy]
EgnyteFile management serverOperations and business supportUS [Privacy Policy]

We will ensure that your personal data is handled safely, securely, and in accordance with your rights, our obligations, and the third party's obligations under the law if any of your personal data is shared with a third party, as described above

In the event that any personal data is conveyed outside of the UK, we will implement appropriate measures to guarantee that your personal data is treated with the same level of security and confidentiality as it would be within the UK.

Your personal data may be transmitted to a third party in the event that we sell, transfer, or merge components of our business or assets. The personal data that we have collected may be utilised in the same manner by the new owner of our business, as outlined in this Privacy Policy.

If we are involved in legal proceedings or are complying with legal obligations, a court order, or the instructions of a government authority, we may be legally obligated to share certain personal data, which may include yours, in certain limited circumstances.

We mandate that all third parties adhere to the law and maintain the security of your personal data. We strictly prohibit our third-party service providers from using your personal data for their own purposes and only authorise them to process it for the specified purposes and in accordance with our instructions.

International Transfers

Some of our service providers are based outside the UK, and their processing may involve data transfers out of the UK. We ensure these transfers comply with data protection laws and employ specific contracts to maintain the same level of data protection. If you require additional information regarding the specific mechanism we employ when transferring your personal data outside of the United Kingdom, please do not hesitate to contact us.

Data Security

We have put in place security measures to prevent data loss, unauthorized access, or misuse. Access to your data is limited to employees, agents, and contractors with a business need. We also have procedures to handle any suspected data breaches.

Data Retention

What is the duration of your use of my personal data?

Your personal data will be retained for the duration that is deemed reasonable to fulfil the purposes for which it was collected, including the fulfilment of any legal, regulatory, tax, accounting, or reporting requirements. In the event of a complaint or if we have a reasonable belief that there is a possibility of litigation in relation to our relationship with you, we may retain your personal data for an extended period.

The retention period for personal data is determined by the following factors: the quantity, nature, and sensitivity of the data, the potential risk of harm from unauthorised use or disclosure, the purposes for which the data is processed and whether those purposes can be achieved through alternative methods, and the relevant legal, regulatory, tax, accounting, or other requirements.

We are required by law to retain fundamental information about our customers, such as their contact, identity, financial, and transaction data, for a period of six years after they cease to be customers for tax purposes.

In certain situations, you may request that we delete your data; for additional details, please refer to [your legal rights] below.

We may anonymise your personal data for research or statistical purposes in certain situations, ensuring that it cannot be associated with you. In such cases, we may continue to use the information indefinitely without providing you with any additional information.

Your Legal Rights

Depending on the circumstances, you may have rights including:

  • Requesting Access:To receive a copy of the personal data we hold about you.
  • Requesting Correction or Erasure:To correct or remove personal data, under certain conditions.
  • Objecting to Processing:For reasons related to your particular situation.
  • Restricting Processing:Suspending processing of your data in certain scenarios.
  • Requesting Transfer:Receiving your data in a machine-readable format.
  • Withdrawing Consent:To withdraw consent where this is the basis of processing.

You can exercise these rights by contacting us at dataprivacymanager@bleuno.com.

Typically, there is no fee.
There will be no charge for accessing your personal data or exercising any of the other privileges. Nevertheless, we reserve the right to impose a reasonable fee if your request is manifestly unfounded, repetitive, or excessive. In these circumstances, we may decline to comply with your request.

What we may require from you

In order to verify your identity and guarantee your right to access your personal data (or to exercise any of your other rights), we may require specific information from you. This is a security measure to prevent the disclosure of personal data to any individual who is not authorised to receive it. Additionally, we may reach out to you to request additional information regarding your request in order to expedite our response.

Response time limit
We endeavour to address all legitimate requests within one month. In the event that your request is particularly intricate or you have submitted multiple requests, it may take us longer than a month to respond. If this occurs, we will inform you and provide you with updated information.

Glossary

  • Legitimate Interest:The business interest in conducting and managing our operations while considering and balancing potential impacts on you.
  • Performance of Contract:Processing data necessary to fulfill a contract with you.
  • Complying with Legal Obligation:Processing data to meet legal requirements.

Lawful Basics

Our business's legitimate interest is the interest of our business in conducting and managing our business in order to provide you with the best possible service/product and the most secure experience. Before processing your personal data for our legitimate interests, we ensure that we account for and balance any potential impact on you (both positive and negative) and your rights. We do not utilise your personal data for activities that are not in our best interest due to the potential impact on you, unless we have obtained your consent or are otherwise compelled or approved by law. By contacting us, you may obtain additional information regarding our evaluation of our legitimate interests in relation to any prospective impact on you in relation to specific activities.

Processing your data is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract, which is referred to as "performance of contract."

To comply with a legal obligation, we must process your personal data when it is required for the fulfilment of a legal obligation to which we are subject.

Third Parties

External Third Parties

Service providers who provide IT and system administration services, including those situated in the UK, EU, USA, and New Zealand, as outlined in Section 5 above.

Professional advisers, such as lawyers, bankers, auditors, and insurers, who are based in the United Kingdom and provide consultancy, banking, legal, insurance, and accounting services, and HM Revenue & Customs, regulators, and other authorities who are based in the United Kingdom and require reporting of processing activities in certain circumstances and are acting as processors or joint controllers.

Your Legal Rights

You are entitled to:
Request access to your personal data, which is commonly referred to as a "data subject access request." This permits you to obtain a copy of the personal data that we maintain about you and to verify that we are lawfully processing it.

Please request that the personal data we have on file for you be corrected. Despite the fact that we may need to verify the veracity of the new data you provide to us, this allows you to have any incomplete or inaccurate data we hold about you corrected.

Request the deletion of your personal information. This allows you to request the deletion or removal of personal data from our systems in cases where there is no valid reason for us to continue processing it. Additionally, you have the right to request that we delete or remove your personal data in the event that you have successfully exercised your right to object to processing (see below), in the event that we have unlawfully processed your information, or in the event that we are obligated to erase your personal data to uphold local law. Please be advised, however, that we may not always be able to accommodate your request for erasure due to specific legal reasons. If this is the case, you will be informed at the time of your request.

You may object to the processing of your personal data if we are relying on a legitimate interest (or those of a third party) and there is a specific aspect of your circumstance that you believe affects your fundamental rights and freedoms. Additionally, you have the right to object in cases where we are using your personal data for direct marketing purposes. In certain instances, we may be able to prove that we have compelling legitimate reasons to process your information that supersede your rights and freedoms.

Request the restriction of the processing of your personal data. This allows you to request that we suspend the processing of your personal data in the following scenarios: · If you wish for us to verify the accuracy of the data.

If our use of the data is unlawful but you do not wish for us to delete it.

In the event that you require us to retain the data in order to establish, exercise, or defend legal claims, even if we no longer require it. · If you have objected to our use of your data, we must determine whether we have overriding legitimate grounds to continue using it.

Request the transfer of your personal data to you or to a third party. We will provide your personal data in a structured, commonly used, machine-readable format to you or a third party that you have selected. It is important to note that this right is only applicable to automated information that you initially provided consent for us to use or that we used to fulfil a contract with you.

You may revoke your consent at any time if we are relying on it to process your personal data. Nevertheless, the lawfulness of any processing that was conducted prior to your withdrawal of assent will not be impacted. We may be unable to offer you specific products or services if you withdraw your consent. At the moment you withdraw your assent, we will inform you if this is the case.

Contact Information

For any privacy-related concerns or requests, please reach out to our Data Privacy Manager at:

  • Email: dataprivacymanager@bleuno.com